|
209201
|
5.5 |
MEDIUM
Local
|
linux debian starwindsoftware
|
linux_kernel debian_linux starwind_san_\&_nas command_center starwind_virtual_san starwind_hyperconverged_appliance
|
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denia…
|
-
|
CVE-2020-25704
|
2024-11-21 14:18 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209202
|
4.1 |
MEDIUM
Local
|
linux redhat debian starwindsoftware
|
linux_kernel enterprise_linux debian_linux starwind_virtual_san
|
A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access …
|
-
|
CVE-2020-25656
|
2024-11-21 14:18 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209203
|
9.8 |
CRITICAL
Network
|
ucms_project
|
ucms
|
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25537
|
2024-11-21 14:18 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209204
|
5.0 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
hw/usb/hcd-ohci.c in QEMU 5.0.0 has a stack-based buffer over-read via values obtained from the host controller driver.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-25624
|
2024-11-21 14:18 |
2020-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209205
|
7.5 |
HIGH
Network
|
libvncserver_project redhat debian
|
libvncserver enterprise_linux debian_linux
|
A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a fl…
|
CWE-369
Divide By Zero
|
CVE-2020-25708
|
2024-11-21 14:18 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209206
|
5.5 |
MEDIUM
Local
|
cyberark
|
endpoint_privilege_manager
|
CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-25738
|
2024-11-21 14:18 |
2020-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209207
|
6.3 |
MEDIUM
Local
|
spice-space debian fedoraproject
|
spice-vdagent debian_linux fedora
|
A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice…
|
CWE-362
Race Condition
|
CVE-2020-25653
|
2024-11-21 14:18 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209208
|
5.5 |
MEDIUM
Local
|
spice-space debian fedoraproject
|
spice-vdagent debian_linux fedora
|
A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any …
|
-
|
CVE-2020-25652
|
2024-11-21 14:18 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209209
|
6.4 |
MEDIUM
Local
|
spice-space debian fedoraproject
|
spice-vdagent debian_linux fedora
|
A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active fil…
|
-
|
CVE-2020-25651
|
2024-11-21 14:18 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209210
|
5.5 |
MEDIUM
Local
|
spice-space debian fedoraproject
|
spice-vdagent debian_linux fedora
|
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path …
|
-
|
CVE-2020-25650
|
2024-11-21 14:18 |
2020-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|